Skip to content

Security: resteasy/resteasy-microprofile

SECURITY.md

Security Policy

The RESTEasy community and our sponsor, Commonhaus Foundation, take security bugs very seriously

We aim to take immediate action to address serious security-related problems that involve our projects.

Reporting Security Issues

When reporting a security vulnerability, it is important not to accidentally broadcast to the world that the issue exists, as this makes it easier for people to exploit it. The software industry uses the term embargo to describe the time a security issue is known internally until it is public knowledge.

Do not open a public issue, send a public pull request, or disclose any information about the suspected vulnerability publicly, including in your own publicly visible git repository.

Preferred Method: GitHub Private Vulnerability Reporting

The preferred way to report security issues is to use GitHub's Private Vulnerability Reporting feature.

  1. Navigate to the RESTEasy Advisories page.
  2. Click Report a vulnerability.
  3. Fill out the provided form with as much detail as possible, including steps to reproduce.

This creates a secure, private channel between you and the RESTEasy maintainers. If you would like to collaborate on a fix, this method allows us to seamlessly invite you to a temporary private fork where we can safely work on the code together.

Alternative Method: Email

If you are unable to use GitHub to report the issue, you may email resteasy-security@redhat.com. If you wish to collaborate on a fix via this method, please include your GitHub username in the email so we can grant you access to a secure workspace.

If you discover any publicly disclosed security vulnerabilities, please notify us immediately through the GitHub reporting tool or via email.

There aren't any published security advisories